Skip to content

R15D: bind MCP product runtime to existing Windows TPM anchor - #204

Merged
bitmaster162 merged 1 commit into
masterfrom
agent/r15d-mcp-r15-runtime-binding-r1
Sep 20, 2026
Merged

bitmaster162 merged 1 commit into
masterfrom
agent/r15d-mcp-r15-runtime-binding-r1

Conversation

@bitmaster162

@bitmaster162 bitmaster162 commented Sep 20, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • bind the packaged MCP product path to an already-provisioned R15 Windows TPM monotonic anchor through explicit startup configuration
  • require an explicit external R14 witness path, controller profile path + pinned SHA-256, and DPAPI custody path
  • reconstruct the reviewed R15B active profile deterministically and perform read-only startup hardware identity/digest verification
  • inject the resulting MonotonicExecutionAnchor into GateBroker
  • fail closed on incomplete configuration, controller/custody mismatch, or hardware binding mismatch
  • preserve the existing prohibition on MCP self-approval surfaces (approve, confirm, override, human_override remain absent)

Exact patch identity

  • base: ed7a763a2ad7f5fa74067b71d298f16d10a410d4
  • head: 2189e488e4d4168537d93f96f8658f6fbebd0c32
  • tree: 7f5dff59404396b82dc20a7cebd29058fd5e449d
  • 1 commit ahead / 0 behind
  • 3 files, +506 / -5
  • patch bytes: 21333
  • patch SHA-256: bc3a2788d8f981338fd7728150e16c16a3aa8d1867d972c4500e1b6407bfb3ed

Validation

  • targeted MCP/R15D: 13 passed
  • GateBroker + MCP + R14/R15/R15B/R15D + remote MCP: 178 passed, 1 skipped
  • full repository: 2314 passed, 2 skipped, 19 subtests passed
  • git diff --check: PASS
  • py_compile: PASS

Natural exact-head CI

For 2189e488e4d4168537d93f96f8658f6fbebd0c32:

  • Ubuntu / Python 3.11: SUCCESS
  • Windows / Python 3.11: SUCCESS
  • Analyze Python: SUCCESS
  • offline-shadow-continuity: SUCCESS
  • CodeQL: SUCCESS
  • review-gates workflow: SUCCESS
  • P0 Unified Shadow Continuity workflow: SUCCESS
  • reviews: 0
  • review threads: 0

Real hardware read-only proof

The new startup factory was exercised against the current provisioned hardware in read-only mode only:

  • provider: TPM2_NV_EXTEND
  • NV public/name identity matched the pinned controller profile
  • observed current GEN3 digest: 3a98c18dff65635c51e24e40458d7b1591acfcdc0eca02be30b077c215f58956
  • no TPM/NV mutation occurred

Live authority state

Live GEN3 files were identical before/after validation:

  • ledger b9fb685aa6497db94c896146e1f7615f594a2dd4d6ba1090d2c578e61c31351b
  • registry 932a94b0786a5461c26aa72b02f70f0a2deec780f700a7b6f36ab61fd000e395
  • witness 8129f32d6971f425026de449f13158bf74702181332e704958c4f5e55422130e
  • controller profile d732c991382a2edb99b9dcb39063224c2a62df2c56813668e76a74444c2965d4
  • custody 49332781cffda2e7aec3a5ab7d41f4f0cd7b880ba2118b2e29492fb049917b98

Authority boundary

This PR does not authorize or perform provisioning, DefineSpace, primer, NV_Extend, Clear, Undefine, live ledger/witness writes, reboot, deploy, trading, or capital actions.

Ready-for-review transition authorized after exact-head CI became fully green. Merge remains separately gated and is NOT authorized by this transition.

@bitmaster162
bitmaster162 marked this pull request as ready for review September 20, 2026 14:41
@bitmaster162
bitmaster162 merged commit 73ff739 into master Sep 20, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant